update.exe

Novosoft LLC

It runs as a separate (within the context of its own process) windows Service named “Novosoft Update Service”.
Publisher:
Novosoft LLC  (signed and verified)

MD5:
1009663cf91583209bf48ed1148709a6

SHA-1:
a4ee75d0710a5531f03a52393c6346d2dd32656f

SHA-256:
d109341ca2f8fc4c0aeba065391cf54fc078053dbaaaeee88b167feb9e61890f

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 2:57:15 PM UTC  (today)

File size:
160.6 KB (164,488 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\novosoft\handy backup 7\update.exe

Digital Signature
Signed by:

Authority:
COMODO CA Limited

Valid from:
11/20/2011 8:00:00 PM

Valid to:
11/20/2012 7:59:59 PM

Subject:
CN=Novosoft LLC, OU=Production, O=Novosoft LLC, STREET=4 Prospekt Akademika Koptyuga, L=Novosibirsk, S=N/A, PostalCode=630090, C=RU

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B67A062D3432D74DE552E81F0271548A

File PE Metadata
Compilation timestamp:
12/2/2011 8:02:07 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
10.0

CTPH (ssdeep):
3072:I56eVnG2ZOjIHVMaQ2jFFyWnd7+0fchRennZpa4v38C9a2OlaqHKZ6bv:I56eVNcjIHVvQ2hFyWnd7+0fchUnZ3dA

Entry address:
0x18C24

Entry point:
E8, 5A, 04, 00, 00, E9, B3, FD, FF, FF, FF, 25, 14, B3, 41, 00, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 18, 50, 42, 00, 33, C5, 50, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 50, 64, FF, 35, 00, 00, 00, 00, 8D, 44, 24, 0C, 2B, 64, 24, 0C, 53, 56, 57, 89, 28, 8B, E8, A1, 18, 50, 42, 00, 33, C5, 50, 89, 65, F0, FF, 75, FC, C7, 45, FC, FF, FF, FF, FF, 8D, 45, F4, 64, A3, 00, 00, 00, 00, C3, 8B, 4D, F4, 64, 89, 0D, 00...
 
[+]

Code size:
103 KB (105,472 bytes)

Service
Display name:
Novosoft Update Service

Service name:
NSUpdate

Description:
Keeps your Novosoft software up to date.

Type:
Win32OwnProcess

Depends on:
NSBackupCoordinator


Scan update.exe - Powered by Reason Core Security